#VU69240 OS Command Injection in xterm - CVE-2022-45063
Published: November 11, 2022
xterm
invisible-island.net
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing font ops. A remote attacker can trick the victim into opening a specially crafted file and execute arbitrary OS commands on the target system within the vi line-editing mode of Zsh.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.